nerdexam
Cisco

300-740 · Question #49

Refer to the exhibit. An engineer must analyze a segmentation policy in Cisco Secure Workload. What is the result of applying the policy?

The correct answer is B. HR cannot use Telnet to connect to IT by using Rule #2. Option B is correct because Cisco Secure Workload evaluates segmentation rules top-down in order, and Rule #2 explicitly denies Telnet (port 23) traffic from the HR scope to the IT scope - so that rule matches and is applied before any subsequent rules are considered. Why the…

Network and Cloud Security

Question

Refer to the exhibit. An engineer must analyze a segmentation policy in Cisco Secure Workload. What is the result of applying the policy?

Exhibit

300-740 question #49 exhibit

Options

  • AThe default catch-all rule is applied by using Rule #3.
  • BHR cannot use Telnet to connect to IT by using Rule #2.
  • CHR can use Telnet to connect to IT by using Rule #1.
  • DThe explicit deny all rule is applied.

How the community answered

(28 responses)
  • A
    7% (2)
  • B
    75% (21)
  • C
    4% (1)
  • D
    14% (4)

Explanation

Option B is correct because Cisco Secure Workload evaluates segmentation rules top-down in order, and Rule #2 explicitly denies Telnet (port 23) traffic from the HR scope to the IT scope - so that rule matches and is applied before any subsequent rules are considered.

Why the distractors are wrong:

  • A is incorrect because the catch-all Rule #3 is never reached for this traffic - Rule #2 already matches and terminates evaluation for Telnet from HR to IT.
  • C is incorrect because even if Rule #1 permits general connectivity between HR and IT, Rule #2 introduces a more specific deny for Telnet that is encountered in the rule order and overrides any broader permit - Telnet is blocked, not allowed.
  • D is incorrect because an explicit deny-all would require a rule that denies all traffic from any source to any destination; what applies here is a specific deny rule (#2), not a blanket deny-all policy.

Memory tip: Think of Secure Workload policies like a bouncer checklist - the first rule that matches the traffic wins, and the line stops there. When a specific "deny Telnet" rule sits above a general "allow" or catch-all, Telnet never makes it past the door.

Topics

#Segmentation Policy#Access Control Rules#Rule Precedence#Workload Protection

Community Discussion

No community discussion yet for this question.

Full 300-740 Practice